Jared Hanson

6.3K posts

Jared Hanson banner
Jared Hanson

Jared Hanson

@jaredhanson

Co-founder @keycardlabs. 🛠️ @passportjs. ❤️ HTTP 401-403. #openid #oauth #wimse #mcp #x402

San Francisco, CA شامل ہوئے Temmuz 2006
2.3K فالونگ3.1K فالوورز
Jared Hanson
Jared Hanson@jaredhanson·
There’s a big difference between auth for agents, and auth for MCP. I want to hear people’s experience with the former.
English
1
0
1
87
Jared Hanson
Jared Hanson@jaredhanson·
SOAP had this same issue. Ultimately people moved off it and dropped RPC semantics.
English
1
0
1
234
Jared Hanson
Jared Hanson@jaredhanson·
The latest changes to MCP paradoxically make the protocol both better and more crufty. For instance, many RPC params are now duplicated as HTTP headers.
English
1
0
0
255
yenkel
yenkel@yenkel·
this is what @woloski told me about what he is going through at @portalbosque_ he used AI and specifically openclaw to automate a lot, write a lot of software, got everyone on chat the surface area has grown so much that he now needs more people. from a scope perspective, he could get a lot more done. from a time perspective, he got to this point a lot faster than he would have without AI. so that accelerated things, but also makes him need help sooner
Dan Shipper 📧@danshipper

We’ve automated every single thing we can @every with AI agents. And yet there’s way more human work to do than ever. We’ve gone from 4 -> 30 human employees since GPT-3. I wrote a report on the structural reasons: how AI makes expert competence cheap, why that drives up demand for experts, and why the dynamic only intensifies as we approach AGI. After Automation: every.to/p/after-automa…

English
2
1
18
6.6K
Kyle Mistele 🏴‍☠️
Kyle Mistele 🏴‍☠️@0xblacklight·
I recently chose one vendor over a second because the first one had a more robust API and in an afternoon codex has built a pulumi provider around their API for me so that all our configs in their SaaS are managed with declarative code that's version-controlled, type-safe, and explicit for agents (instead of needing their CLI/MCP server) and plugs into our other IaC so we don't need to go do things in dashboards and then configure it in our IaC this is what headless SaaS for agents means btw not "ship an MCP server" let me (or codex) configure it with code code mode for SaaS if you will - IaC for SaaS configuration
English
6
3
75
22.7K
Rhys
Rhys@RhysSullivan·
I've got questions for the people having agents write software for their team: - Where do you deploy it? - How are you giving it access to integrations? - How are you managing access controls? Diving deep on this topic atm, if you're a company struggling with this let me know
English
23
1
57
9.5K
Jared Hanson
Jared Hanson@jaredhanson·
When credentials expire in minutes, there’s no need to vault them.
English
0
0
0
226
Jared Hanson
Jared Hanson@jaredhanson·
Turns out it’s safer to execute code from an LLM than from npm.
English
0
0
9
305
Matthew Phillips
Matthew Phillips@matthewcp·
Drop any Hono middleware into your Astro pipeline. Logging, auth, rate limits, wherever you want them. Astro's stages are just middleware now.
Matthew Phillips tweet media
English
8
27
274
27.7K
fks
fks@FredKSchott·
Blown away by the response to flueframework.com over the last 24hr. Feels like we're onto something special here. Grateful to everyone who's tried it, shared it, or sent feedback. We're already on PR #35... 😅
English
17
13
427
21K
Jared Hanson
Jared Hanson@jaredhanson·
@yenkel @dwarkesh_sp Same. I may be feeling more inadequate than weak, seeing how the LLM is able to grasp and explain concepts much more quickly.
English
0
0
1
128
yenkel
yenkel@yenkel·
@jaredhanson I use LLMs a lot while reading about topics and digging in, so it makes my reading even more valuable e.g. when reading @dwarkesh_sp's book I used LLMs a lot to understand concepts sometimes is awkward with the phone. voice or in the glasses might be better
English
1
0
0
217
Jared Hanson
Jared Hanson@jaredhanson·
I like to read. And I like to deeply understand the details. I sometimes worry this is a weakness in the LLM era. Anyone else feel this way?
English
2
0
2
388
Dominik Tornow
Dominik Tornow@DominikTornow·
pi agent by @badlogicgames is the modern smalltalk, a developer environment and runtime that extends itself. Unlike smalltalk, you don't code what you want, you just say what you want
Dominik Tornow@DominikTornow

Built an extension for pi.dev on @resonatehqio's durable functions and durable promises. The agent starts long-running tool calls, keeps working, and is notified on completion. Even if you kill the agent process and resume the session later.

English
3
7
72
9.3K
Tony Dang
Tony Dang@dangtony98·
This would be excellent as well as the ability to generate API keys programmatically would take it a step further. Having both of these endpoints would allow you to implement automatic secrets rotation and, even better, dynamic secrets (creds minted on the fly). More companies should be supporting this; especially in this AI era.
Andrew Qu@andrewqu

underrated: public API token revocation endpoint so easy to lock down a service you use more API services should have this

English
3
1
14
4.7K
Jared Hanson ری ٹویٹ کیا
Thomas H. Ptacek
Thomas H. Ptacek@tqbf·
"Replacing long-lived keys with ephemeral keys is, for my money, one of the best uses of security engineering effort." is the best sentence I've read pertaining to my field in awhile. More at: argemma.com/blog/long-live…
English
6
36
227
28K
Jared Hanson ری ٹویٹ کیا
Braelyn ⛓️
Braelyn ⛓️@braelyn_ai·
sandbox initialization time is such a silly metric to focus on the agent using the sandbox takes 15m but thank god your sandbox is 0.02s faster than the competitors
English
34
9
370
37.8K